
The Cyber Essentials Checklist Explained
Cyber Essentials is the UK Government’s baseline cyber security certification, developed by the National Cyber Security Centre (NCSC) and delivered through IASME. It tests five technical controls: firewalls, secure configuration, security update management, user access control and malware protection.
Certification is a verified self-assessment. You answer a question set covering the five controls, a qualified assessor reviews your answers, and the certificate must be renewed every 12 months.
The controls are defined in the NCSC’s Requirements for IT Infrastructure version 3.3, published in April 2026. Assessment accounts created from 27 April 2026 are assessed against the Danzell question set, which replaced Willow.
This checklist sets out what assessors expect under each control, where applications most often fail, and the documents that support certification. Everything below reflects the scheme as it stands under Danzell and version 3.3.
The Five Controls at a Glance
| Control | What assessors expect | Where applications fail |
|---|---|---|
| Firewalls | Every in-scope device behind a correctly configured boundary or software firewall, default passwords changed, unauthenticated inbound connections blocked by default | Router admin interfaces reachable from the internet, inbound rules with no documented business need |
| Secure configuration | Unnecessary accounts and software removed, auto-run disabled, device locking with brute-force protection | Default credentials left in place, unused guest and admin accounts still enabled |
| Security update management | All software licensed and supported, high-risk fixes applied within 14 days, automatic updates on where possible | Unsupported operating systems in scope, missed 14-day window (automatic fail under Danzell) |
| User access control | Unique accounts, MFA on all cloud services, separate admin accounts, a documented joiner and leaver process | MFA not enabled on a cloud service (automatic fail), admin accounts used for email and browsing |
| Malware protection | Anti-malware active on every in-scope device, or application allow listing enforced through code signing | Devices missed from anti-malware coverage, allow lists that users can bypass |
What Cyber Essentials Certification Involves
The scheme is owned by the NCSC and operated by IASME as its Cyber Essentials delivery partner, working through a network of licensed certification bodies. Standard Cyber Essentials is a self-assessment questionnaire verified by an assessor. Cyber Essentials Plus adds an independent technical audit, including vulnerability scans and hands-on checks that the same five controls are working in practice.
Self-assessment fees start at £320 plus VAT for the smallest organisations and are tiered by organisation size, from micro (0 to 9 employees) up to large (250 or more). Cyber Essentials Plus is priced separately by the certification body based on the size and complexity of your systems.
UK organisations with a turnover under £20 million receive cyber liability insurance included with certification. Certificates are valid for 12 months, so compliance is an annual cycle rather than a one-off project.
Which level you need usually depends on who is asking. Customers and insurers often accept standard certification, while some government and defence contracts specify Plus. Either way, the technical requirements are the same, so the checklist below applies to both.
The Cyber Essentials Checklist Control by Control
The requirements below come directly from version 3.3 of the NCSC requirements document. For each control we have set out what assessors expect and the evidence that makes your answers credible.
1. Firewalls
Every device in scope must be protected by a correctly configured firewall, either a boundary firewall on your network or a software firewall on the device itself. Default administrative passwords must be changed to strong, unique passwords, or remote administrative access disabled entirely.
The administrative interface must not be reachable from the internet unless there is a clear, documented business need and the interface is protected by MFA or an IP allow list. Unauthenticated inbound connections must be blocked by default.
Assessors also expect inbound firewall rules to be approved and documented by an authorised person, with the business need recorded, and rules removed when no longer needed. Staff working on public wifi must have a software firewall enabled on their device.
Evidence to prepare: a firewall rule record showing each open service, who approved it and why, plus confirmation that default credentials have been changed.
2. Secure Configuration
Out-of-the-box settings favour convenience over security, so this control is about hardening. You must remove or disable unnecessary user accounts, change default or guessable passwords, uninstall software you do not need, and disable auto-run features that execute files without user authorisation.
Devices that are unlocked in person need a biometric, password or PIN, protected against brute-force attacks. Version 3.3 expects either throttling that allows no more than 10 guesses in 5 minutes, or a lockout after no more than 10 unsuccessful attempts. Where a credential only unlocks the device, a minimum length of 6 characters applies.
Evidence to prepare: a build or configuration standard for new devices, and a record showing default accounts and passwords were dealt with at setup.
3. Security Update Management
All software in scope must be licensed and supported, and the vendor must publish a date when support will end. Software that goes out of support must be removed, or moved into a segregated sub-set with no traffic to or from the internet.
Automatic updates must be enabled wherever possible. Updates must be applied within 14 days of release where the vendor rates the fix as critical or high risk, where the vulnerability has a CVSS v3 base score of 7 or above, or where the vendor gives no severity details at all.
The definition of software includes operating systems, applications, and the firmware on firewalls and routers. Under the Danzell question set, missing the 14-day window on operating system, firmware or application updates triggers an automatic fail.
Evidence to prepare: a software and firmware inventory with versions and support status, and a patching procedure that names the 14-day timescale.
4. User Access Control
You must have a process to create and approve user accounts, authenticate every user with unique credentials, and remove or disable accounts when they are no longer required, for example when someone leaves. Accounts used by third parties such as your IT support provider count too.
MFA must be implemented where available, and authentication to cloud services must always use MFA. Administrative activity must happen on separate admin accounts that are not used for email or web browsing, and special privileges must be removed when a role changes.
Password rules are specific. Accounts must be protected against brute-forcing, and password quality must be managed by MFA, a 12-character minimum, or an 8-character minimum combined with automatic blocking of common passwords through a deny list. Regular forced expiry and complexity rules should not be used.
Evidence to prepare: a documented joiners, movers and leavers procedure, an admin account register, and a password policy matching the rules above.
5. Malware Protection
A malware protection mechanism must be active on every device in scope. For Windows and macOS devices the usual option is anti-malware software, kept up to date in line with vendor recommendations and configured to prevent malware running, block malicious code and prevent connections to malicious websites.
The alternative is application allow listing, where only approved applications restricted by code signing can execute. You must approve applications before deployment, maintain a current approved list, and prevent users installing anything unsigned.
Evidence to prepare: proof of anti-malware deployment across the full device estate, or your approved application list and the approval process behind it.
Scope: What the Assessment Must Cover
Certification should cover the whole IT infrastructure used for your business, or a well-defined and separately managed sub-set. A scope that excludes end-user devices is not acceptable, and you must justify any partial scope to your assessor.
Cloud services cannot be excluded from scope under any circumstances. Staff-owned devices that access organisational data or services are in scope too, unless they are used only for calls, texts or MFA applications.
For home workers, the ISP router is out of scope, which is why a software firewall on the user device matters. If a corporate VPN is used, the internet boundary sits on the company firewall instead.
The Danzell Question Set from April 2026
Danzell applies to every assessment account created from 27 April 2026. Accounts opened before that date could finish against the outgoing Willow set, with six months from account creation to complete.
The headline changes are the first automatic-fail questions the scheme has had, covering MFA on cloud services and the 14-day update window, plus a formal definition of cloud services and confirmation that they can never be excluded from scope. Our guide to the Cyber Essentials 2026 question set changes works through each change and what to check before you recertify.
Common Failure Points in Cyber Essentials Assessments
Assessors see the same problems repeatedly. Before applying, check your organisation against this list:
- Unsupported software: an old operating system or application still in scope with no vendor security fixes
- Missed update windows: critical or high-risk fixes applied later than 14 days after release, now an automatic fail
- Cloud accounts without MFA: a single cloud service where MFA is available but not enabled, also an automatic fail
- Shared or stale accounts: shared logins, or leavers whose accounts were never disabled
- Admin sprawl: too many administrator accounts, or admins using privileged accounts for day-to-day email and browsing
- Default credentials: routers, firewalls and devices still on factory passwords
- Unmanaged BYOD: personal devices accessing company data with no controls applied
- An incomplete asset picture: no reliable list of devices, software versions and cloud services, which makes every other answer guesswork
Most of these failures trace back to the same root cause: nobody owns the process. A named person responsible for patching, account reviews and the asset register, backed by written procedures, removes the majority of first-attempt failures.
Evidence and Documentation That Support Certification
Cyber Essentials does not demand a full management system, but the question set assumes documented processes sit behind your answers. Assessors expect you to describe how accounts are created and approved, how firewall rules are authorised, how quickly you patch, and how personal devices are controlled.
The core set includes an information security policy, access control and password policies, a patch and vulnerability management procedure, BYOD and remote working policies, an asset register and an incident response plan. We list the full set, and what each document needs to say, in our guide to the documents required to pass Cyber Essentials.
The same documentation supports your obligations under Article 32 of the UK GDPR, which requires appropriate technical and organisational measures to secure personal data. A certified control set with written procedures is strong evidence of both.
Cyber Essentials and Government Contracts
Under Procurement Policy Note 014, central government departments, their executive agencies and non-departmental public bodies, and NHS bodies must require Cyber Essentials or Cyber Essentials Plus for contracts with certain characteristics. These include handling citizens’ personal data, government employees’ personal information, or ICT systems processing data at OFFICIAL level.
Evidence of certification is required before contract award, and suppliers must recertify every 12 months to stay compliant. The policy dates back to 2014, when certification first became mandatory for in-scope central government contracts, and many local authorities and private sector supply chains now ask for it as standard.
IASME also operates a broader standard, IASME Cyber Assurance, which builds on the same controls and adds risk management, incident response and data protection governance for organisations that want assurance beyond the baseline.
Cyber Essentials Policy and Procedure Writers
Policy Pros writes the documentation that sits behind Cyber Essentials certification. Our Cyber Essentials policy writing service covers the full supporting set: information security, access control, passwords, patch management, BYOD, asset management and incident response, each aligned to the current question set.
For organisations building a wider security framework, our IT security policy writing service maps your documentation to NCSC guidance and prepares you for Cyber Essentials Plus, IASME Cyber Assurance or ISO 27001. Every document is written in plain English and tailored to the systems you actually run.
Contact Policy Pros to discuss the policies and procedures you need before your next Cyber Essentials assessment.
Frequently Asked Questions
What is on the Cyber Essentials checklist?
The Cyber Essentials checklist covers five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. Under each control the NCSC's Requirements for IT Infrastructure v3.3 sets specific expectations, such as blocking unauthenticated inbound connections, applying high-risk updates within 14 days and enabling MFA on all cloud services.
What are the Cyber Essentials requirements in 2026?
From 27 April 2026 the requirements are set by version 3.3 of the NCSC requirements document, assessed through the Danzell question set. Key requirements include MFA on every cloud service where available, critical and high-risk updates applied within 14 days, cloud services always in scope, and separate administrator accounts. MFA on cloud services and the 14-day update window are now automatic-fail questions.
How much does Cyber Essentials certification cost?
Standard Cyber Essentials self-assessment starts at £320 plus VAT for the smallest organisations, with fees tiered by organisation size from micro (0 to 9 employees) to large (250 or more). Cyber Essentials Plus is priced by the certification body based on the size and complexity of your systems. UK organisations with turnover under £20 million receive cyber liability insurance included with certification.
Is Cyber Essentials compliance mandatory?
There is no general legal requirement, but under Procurement Policy Note 014 central government bodies and NHS organisations must require Cyber Essentials or Cyber Essentials Plus for contracts involving personal data or ICT systems handling OFFICIAL information. Many local authorities, insurers and private sector supply chains also ask for certification as a condition of doing business.
How long does a Cyber Essentials certificate last?
A Cyber Essentials certificate is valid for 12 months. Organisations must recertify annually, and because the question set is updated over time, each renewal should be checked against the current requirements. Renewals purchased from 27 April 2026 onwards are assessed against the Danzell question set.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Standard Cyber Essentials is a self-assessment questionnaire verified by a qualified assessor. Cyber Essentials Plus tests the same five controls but adds an independent technical audit, including vulnerability scans and hands-on checks of devices, patch levels and malware defences. Both certifications are valid for 12 months.